Creates or updates a DingTalk chatbot notification configuration.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:CreateOrUpdateDingTalk |
create |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Id |
integer |
No |
The ID of the chatbot. Note
Call DescribeDingTalk to query chatbot IDs. |
1589 |
| RuleActionName |
string |
Yes |
The name of the chatbot. Note
Must be 2 to 64 characters. |
testNotify |
| SendUrl |
string |
Yes |
The webhook URL. |
https://oapi.dingtalk.com/robot/send?access_token=XXX |
| IntervalTime |
integer |
No |
The notification interval. Note
0 indicates no limit. |
0 |
| ConfigList |
string |
No |
Alert notification settings. JSON array with the following fields:
Note
See the additional parameter descriptions below. |
[{"type":"sas_analysis_online-sas-operation-log-sas-event-suspicious","configItemList":[{"key":"item_level","valueList":["all"]},{"key":"event_type","valueList":["all"]}]}] |
| GroupIdList |
string |
No |
Asset group IDs for notification targeting. JSON array. Note
Call DescribeGroupStruct to query asset group IDs. |
["10417151"] |
| DingTalkLang |
string |
No |
Notification language. Valid values:
|
zh |
Additional description of parameters
| type | Description | key | Description | valueList | Description |
| sas_analysis_online-sas-operation-log-sas-event-vul | Vulnerabilities | type | Vulnerability type | all | All |
| cms | Web-CMS vulnerability | ||||
| oval | Linux software vulnerability | ||||
| sys | Windows system vulnerability | ||||
| emg | Urgent vulnerability | ||||
| necessity | Risk level | all | All | ||
| asap | High | ||||
| later | Medium | ||||
| nntf | Low | ||||
| sas_analysis_online-sas-operation-log-sas-event-hc | Baseline risks | item_level | Risk level | all | All |
| high | High | ||||
| medium | Medium | ||||
| low | Low | ||||
| sas_analysis_online-sas-operation-log-sas-event-suspicious | Alerts | item_level | Severity | all | All |
| serious | Critical | ||||
| suspicious | Suspicious | ||||
| remind | Remind | ||||
| event_type | Alert type | ||||
| all | All | ||||
| Suspicious process | Suspicious process | ||||
| Webshell | Webshell | ||||
| Unusual logon | Unusual logon | ||||
| Exception | Exception | ||||
| Sensitive file tampering | Sensitive file tampering | ||||
| Malicious process (cloud threat detection) | Malicious process (cloud threat detection) | ||||
| Unusual network connection | Unusual network connection | ||||
| Others | Others | ||||
| Abnormal account | Abnormal account | ||||
| Application intrusion event | Application intrusion event | ||||
| Cloud threat detection | Cloud threat detection | ||||
| Precision defense | Precision defense | ||||
| Application whitelist | Application whitelist | ||||
| Persistent webshell | Persistent webshell | ||||
| sas_analysis_online-sas-operation-log-sas-event-ak-leakage | AccessKey pair leaks | type | Leak type | all | All |
| sas_analysis_online-sas-operation-log-sas-event-honeypot | Alerts generated by cloud honeypot | item_level | Risk level | all | All |
| high | High | ||||
| medium | Medium | ||||
| low | Low | ||||
| sas_analysis_online-sas-operation-log-sas-event-rasp | Alerts generated by application protection | item_level | Risk level | all | All |
| high | High | ||||
| medium | Medium | ||||
| low | Low |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| RequestId |
string |
The request ID. |
76975B7A-34DC-5CB6-9538-91700D4F112E |
Examples
Success response
JSON format
{
"RequestId": "76975B7A-34DC-5CB6-9538-91700D4F112E"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.